Privacy Policy
Effective Date: 15 September 2024 | Last Amended: 27 September 2026. Formulated under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000.
1. Legal Framework & Scope
This Privacy Policy governs the processing of personal data by Threxar Intelligence ("Threxar", "We", "Us", or "Our"). Threxar operates as an open threat intelligence and cybercrime research platform.
This policy is formulated in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act 2023"), the Information Technology Act, 2000 ("IT Act 2000"), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and applicable global data protection principles including the General Data Protection Regulation ("GDPR").
By accessing, navigating, or utilizing the services provided on the Threxar website, you acknowledge the collection and processing of data as outlined in this policy.
2. Data Fiduciary & Data Principal Status
Under the DPDP Act 2023, Threxar acts as the Data Fiduciary in respect of personal data submitted directly by visitors ("Data Principals") through our public web portal, contact forms, or intelligence tip submission mechanisms.
Data Principals retain all statutory rights regarding their personal data, including rights of access, correction, erasure, and grievance redressal as specified under Sections 11 to 14 of the DPDP Act 2023.
3. Categories of Personal Data Collected
Communication Data: Full name, professional email address, organization name, and inquiry content voluntarily submitted via our contact or tip disclosure forms.
Technical Network Telemetry: Internet Protocol (IP) addresses (anonymized or hashed), HTTP user-agent strings, access timestamps, request URIs, and referrers collected automatically for web application firewall (WAF) protection and operational analytics.
No Sensitive Personal Data: Threxar does NOT collect or process passwords, financial records, credit/debit card numbers, biometric identifiers, official government identification numbers, or health records of site visitors.
4. Lawful Basis & Purposes of Processing
Consent & Direct Fulfillment: Processing contact and tip form submissions based on explicit voluntary consent to address threat inquiries or security disclosures.
Legitimate Cyber Security Interests: Processing technical network telemetry to detect malicious automated scraping, brute force attempts, Distributed Denial of Service (DDoS) attacks, and unauthorized system access.
Statutory Obligations: Compliance with mandatory cybersecurity incident reporting standards mandated under Section 70B of the IT Act 2000 and directives issued by the Indian Computer Emergency Response Team (CERT-In).
5. Technical Security Practices & Data Protection
In accordance with Section 43A of the IT Act 2000 and Rule 8 of the SPDI Rules, Threxar maintains comprehensive technical, organizational, and physical security measures.
Data Encryption: Transport Layer Security (TLS 1.3) protocol for data in transit and AES-256 bit encryption algorithms for stored database records.
Access Controls: Strict role-based access control (RBAC), multi-factor authentication (MFA), and automated audit logging for all administrative data access.
6. Data Retention Schedule
Contact & Tip Inquiries: Retained for up to 90 days following inquiry resolution, after which communications are permanently deleted unless ongoing legal or security proceedings require extension.
Technical & Firewall Logs: Security access logs and anonymized IP telemetry are retained for up to 180 days to comply with statutory CERT-In cybersecurity log retention directives.
Aggregated Analytics: Non-personally identifiable site usage metrics are retained in aggregated form for performance monitoring.
7. Data Sharing & Cross-Border Transfers
Zero Data Commercialization: Threxar does NOT sell, lease, rent, or trade personal data to any third-party advertisers, brokers, or marketing entities under any circumstances.
Law Enforcement Compliance: Personal data may be disclosed to statutory Indian law enforcement agencies or judicial authorities only pursuant to valid legal orders, summons, or directives issued under Section 91 of the Code of Criminal Procedure, 1973 (CrPC) / Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS).
Cross-Border Infrastructure: Server infrastructure and backup nodes adhere to Section 16 of the DPDP Act 2023 for lawful cross-border data processing.
8. Statutory Rights of Data Principals
Right to Access: Request a summary of personal data being processed by Threxar along with the processing activities.
Right to Correction & Completion: Request rectification of inaccurate or misleading personal data.
Right to Erasure: Request permanent deletion of personal data where processing is no longer required for statutory or contractual purposes.
Right of Grievance Redressal: Seek resolution for any privacy concerns through our designated Grievance Officer.
9. Grievance Officer & Contact Information
In accordance with Rule 5(9) of the IT SPDI Rules 2011 and Section 13 of the DPDP Act 2023, any privacy concerns, data access requests, or statutory grievances may be directed to our designated Grievance Officer:
Designation: Grievance Officer & Data Protection Lead, Threxar Intelligence.
Official Channel: Via our secure online portal at /contact or by emailing privacy@threxar.com.
Response Timeline: All statutory privacy requests and grievances will be acknowledged within 24 hours and addressed within 15 working days.